github akitaonrails/ai-jail v2.4.0

one hour ago

A security release. It resolves both open advisories in full and the
release-blocking findings from the 2026-09-30 source audits. No .ai-jail
config field or CLI flag changed; a couple of behaviours now fail closed where
they previously degraded silently (noted below).

Security

Closes GHSA-w976-gw52-hvx2 (five findings) and GHSA-frgp-q3qc-g78p.

  • Worktree metadata can no longer bind an arbitrary host directory
    read-write.
    --worktree validation now requires the linked-worktree layout
    to be genuine — the per-worktree git dir must be <commondir>/worktrees/<name>
    with both paths canonicalized — instead of trusting a repository-authored
    commondir file to name any existing directory. (advisory #1)

  • Duplicate environment entries no longer defeat phantom-secret injection.
    --secret now resolves a bound key with the same last-wins precedence the
    child environment uses, removes every entry for that key, and inserts one
    placeholder. Previously a later KEY=real entry (e.g. a credential file plus
    --env KEY) delivered the real value into the sandbox.

  • A browser command from an untrusted project can no longer clear a trusted
    lockdown.
    The browser profile only clears lockdown when the browser was
    chosen by trusted input (an explicit --browser/global profile, or a command
    on the CLI or from a trusted layer). A command = ["chromium"] in a cloned
    repo's .ai-jail keeps lockdown; run the browser from the CLI to open a
    window. (advisory #3)

  • TIOCSTI is filtered as the kernel reads it. The seccomp rule now compares
    the ioctl request as a 32-bit value, closing a bypass where
    TIOCSTI | (1 << 32) slipped past a 64-bit comparison and still reached the
    same terminal-injection ioctl. (advisory #2)

  • Landlock now scopes abstract Unix sockets and signals (ABI V6,
    best-effort).
    This is the backstop the threat model documented but did not
    apply: without it, --x11/--network left the host's abstract X11 socket
    reachable and --systemd-user left host signalling open. Kernels below V6
    (< 6.12) keep the existing filesystem (V3) and network (V4) enforcement
    unchanged. (advisory GHSA-frgp-q3qc-g78p)

  • macOS: terminal read/write is scoped to this run's own terminals — the
    allocated PTY and the caller's own /dev/tty — not a blanket /dev/ttys*
    grant, so a sandboxed process cannot open another of your terminals by path
    and write escape sequences to it. (advisory #4)

  • macOS: --masked project paths are denied for writes as well as reads, so
    a file the agent cannot read cannot be blindly overwritten through the project
    write allowance either. (advisory #5)

  • The primary-screen escape filter no longer collapses on a doubled
    introducer.
    A fresh ESC now aborts any partial sequence and is never
    forwarded, so ESC ESC ]52;… and ESC [ ESC ]… — which terminals collapse
    into a single introducer — can no longer smuggle an OSC (e.g. a clipboard
    write) past the filter.

  • The proxy's test-only escape hatches are gone from release builds.
    AI_JAIL_TEST_PROXY_ALLOW_PRIVATE (SSRF guard off) and
    AI_JAIL_TEST_PROXY_EXTRA_ROOTS (extra TLS root) are now compiled in only
    under the test-hooks feature; a release build and cargo install contain
    neither the env-var reads nor their strings, so the environment is no longer a
    control channel over them.

Changed (fail closed)

  • Overlay setup failures now abort the launch. A missing overlay source, an
    overlapping destination, or a storage-creation failure previously warned and
    continued with the plain read-write project bind — silently modifying the real
    files a user expected copy-on-write to protect. Overlay storage directories are
    also now collision-resistant (hashed from the canonical destination).

Testing

  • New regression tests for each fix, including runtime seccomp coverage of the
    TIOCSTI high-bit bypass. The filtered-egress and phantom-secret end-to-end
    suites now require --features test-hooks (which enables the hatches above);
    CI runs the suite with that feature, and the files are gated so a plain
    cargo test skips rather than fails them.

Checksums (SHA256)

86a92e4524284fb7210c887655253b98e5a9349699d23c60448fde4336a89ed0  ai-jail-linux-x86_64.tar.gz
74b94c716b8e73080824397c99079ca27e4c88f3713bbc8f9954a527d66d2da1  ai-jail-macos-aarch64.tar.gz

Install

brew tap akitaonrails/tap && brew install ai-jail
yay -S ai-jail-bin
cargo install --locked ai-jail

Don't miss a new ai-jail release

NewReleases is sending notifications on new releases.